Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full takeover of Oracle WebCenter Enterprise Capture leading to loss of confidentiality, integrity, and availability
Action: Immediate Patch
AI Analysis

Impact

A flaw in the a high‑privileged attacker who can reach the system over HTTP to compromise the application. The vulnerability is easily exploitable and results in the attacker gaining full control of the service, effectively enabling remote code execution and administrative takeover. This is a Broken Access Control (CWE‑284) flaw. The CVSS vector indicates a high impact on confidentiality, integrity, and availability. It can also affect additional Oracle Fusion Middleware products due to a scope change.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are components of Oracle Fusion Middleware and are used in enterprise capture workflows.

Risk and Exploitability

The CVSS score of 9.1 reflects critical severity, but the EPSS score of less than 1% indicates that the vulnerability is not widely exploited yet. It is not currently listed in CISA’s KEV catalog. The attack requires network access to the HTTP interface of the Client Bundle and a privileged attacker; once accessed, the attacker the application. This vulnerability represents a Broken Access Control flaw (CWE‑284) that permits privilege escalation.

Generated by OpenCVE AI on September 17, 2026 at 05:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or upgrade to a version of Oracle WebCenter Enterprise Capture that contains the fix as described in Oracle’s security alert
  • Limit HTTP access to the Client Bundle by restricting it to trusted networks or VPNs and configuring firewalls accordingly
  • Disable or tightly restrict the Client Bundle component through configuration changes to enforce the principle of least privilege

Generated by OpenCVE AI on September 17, 2026 at 05:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Broken Access Control Enables Full Control of Oracle WebCenter Enterprise Capture

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:46.769Z

Reserved: 2026-08-31T15:40:57.330Z

Link: CVE-2026-83006

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:43.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:07.223

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses